CVE-2009-2532
57Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 62%
from disclosure to weapon307 days
Published on NVDOct 14
1st PoC+307d
VulnCheck+2806d
exploitation probability
62%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka "SMBv2 Command Value Vulnerability."
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/14674unverifiedexploitdbwww.exploit-db.com/exploits/40280unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.